Cybersecurity
264 articles RSS
Rustls 0.23.44 Enables Post-Quantum ML-DSA Certificates by Default in AWS-LC-RS Provider
Rustls's September 7 release turns on NIST-standardized ML-DSA post-quantum certificates by default for the aws-lc-rs provider, plus a KeyLogFile permissions fix and an ECH certificate-verification fix.
vlt Reaches 1.0, Launching Hosted Package Registries as a Security-First npm Replacement
vlt, a JavaScript package manager built by npm's original developers, ships 1.0 with hosted registries that block malware and phased installs that stop scripts from running automatically.
Attackers Exploit Critical JFrog Artifactory Auth-Bypass Flaw Within Days of Patch
CISA added CVE-2026-82329, a 9.8-severity Artifactory authentication bypass, to its exploited-vulnerabilities catalog days after JFrog patched it.
GitSpawn Flaws Let Malicious .git Configs Run Attacker Code in Claude Code, Cursor, Codex, and Other AI Coding Agents
Manifold Security found eight flaws across seven AI coding agents that let a repository's git config silently execute code the moment it is opened.
IssueTrojanBench Study Finds Malicious GitHub Issues Bypass AI Coding Agent Guardrails Up to 79% of the Time
A Concordia University benchmark found Cursor, Claude Code, and Codex Desktop let malicious GitHub issues bypass their safety guardrails in up to 79.2% of attempts, with GPT-based agents far more vulnerable than Claude Code.
Contrast Security Report Finds AI Application-Security Scanners Agree on Just 5% of Findings
Three AI-powered AppSec scanners run on the same codebase agreed on only 5% of findings, and one scanner reproduced just 17% of its own results on repeat runs, Contrast Security's AppSec Overflow 2026 report finds.
Australia Charges Two Men With 14 Offenses Over TeamPCP's Supply-Chain Hacking Spree That Hit Trivy, LiteLLM and GitHub
AFP, FBI and WA Police charged a 21-year-old and a 23-year-old over the TeamPCP campaign that compromised 1,000+ organizations through open-source developer tools.
Eight Stable Linux Kernels Patch a GSO Fragmentation Flaw Present Since Kernel 2.6.27
CVE-2026-80590, a bug letting unprivileged users trigger a kernel panic via mismarked IPv4/IPv6 fragments, is fixed across eight stable and longterm kernel releases.
Tenet Security's 'GhostJacking' Attack Tricked Claude Code Into Rewriting Cloudflare DNS Records 9 Times Out of 10
Researchers showed AI coding and security agents can be hijacked through poisoned Cloudflare, Datadog, and Sentry logs to rewrite DNS records and steal credentials.
24 Malicious npm Packages Abuse Unpkg and Other Mirrors to Host Fake Cloudflare CAPTCHA Pages
OX Security found 24 npm packages built solely to let mirrors like unpkg serve fake Cloudflare CAPTCHA pages that can redirect to ClickFix-style phishing.
Attackers Actively Exploit Critical Gitea RCE Flaw as CISA Adds It to KEV Catalog With August 28 Deadline
CISA added Gitea's CVE-2026-60004 remote code execution flaw to its KEV catalog after BleepingComputer reported attackers deploying cryptomining malware on unpatched servers.
Microsoft Removes WMIC From Windows 11 24H2 and 25H2, Closing Out a 25-Year-Old Tool Abused as a LOLBIN
Microsoft has pulled the WMIC command-line utility from Windows 11 24H2, 25H2, and 26H1 builds, ending a tool long abused by ransomware and other attackers.